6 ms·
> curl -L "https://replicate.fyi/install-llama-cpp https://replicate.fyi/install-llama-cpp" | bash Seriously? Pipe script from someone's website directly to ba
by guy98238710 3y ago
> curl -L "https://replicate.fyi/install-llama-cpp https://replicate.fyi/install-llama-cpp" | bash
Seriously? Pipe script from someone's website directly to bash?
- madars 3y agoThat's the recommended way to get Rust nightly too: https://rustup.rs/ https://rustup.rs/ But don't look there, there is memory safety somewhere!
- gattilorenz 3y agoYes. If you are worried, you can redirect it to file and then sh it. It doesn’t get much easier to inspect than that…
- cjbprime 3y agoEither you trust the TLS session to their website to deliver you software you're going to run, or you don't.
- alexgartrell 3y agoIMO this is equivalently scary to installing an arbitrary rpm.
- dopidopHN 3y agoPretty common. You can inspect the script before piping it.
- Evidlo 3y agoBad actors can detect if its being piped to bash and send different data. Better to just download the script first if you're concerned.
- selcuka 3y agoHow can you detect where someone pipes the output of curl output to?
- pests 3y agoBasically, bash executes the script line by line as it is downloading - pausing the download while that line executes. By sending a sleep() command early in the script you can detect the delay in the next line beind downloaded. Its a lot more complicated due to TCP buffers and trying to hide output from the user. Original article below. It is giving me a certificate error though but its available through archives or a cache. https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
- mike_ivanov 3y agowho doesn't love surprises